US2005257045A1PendingUtilityA1

Secure messaging system

Individually held — no corporate assignee on recordPriority: Apr 12, 2004Filed: Apr 12, 2005Published: Nov 17, 2005
Est. expiryApr 12, 2024(expired)· nominal 20-yr term from priority
H04L 9/3263G06Q 20/102G06Q 20/04H04L 2209/56H04L 63/12G06Q 20/389G06Q 20/02G06Q 20/388H04L 63/0823H04L 9/321G06Q 20/38215G06Q 20/40G06Q 20/386G06Q 20/384
35
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method for secure data transactions over a computer network is described. In one embodiment, the act of generating at the first party a document, which authorizes the data transaction to proceed is performed. In one embodiment, the document content is signed using a computer network with audit-level encryption digital certificates. In one embodiment, a signed digital message (and/or document) is sent from the first party to the network transfer system electronically, and can be authenticated via the ICN certificate authorities to demonstrate the authorities of the signer of the signed document in assent to the transaction. In one embodiment, a copy of the signed digital document can be stored in a database associated with the transfer network system. In one embodiment, the system uses rules (patterns) of exchange agreed upon within and between organizations. These rules enable the exchange to progress smoothly and drive systematically the attention of participants to demands and problems etc. as a given transaction goes along.

Claims

exact text as granted — not AI-modified
1 . A method for finalizing an electronic fund transfer that is matched to an invoice for payment to be made from a first party having a financial account at a first agent to a second party having a financial account at a second agent using a network transfer system that is in electronic communication with the first party, the second party, the first agent and the second agent, the method comprising: 
 generating at the first party a document which authorizes the payment of the invoice;    signing the document using a first digital certificate in accordance with a certificate authority in communication with the transfer network system;    sending the signed digital document from the first party to the network transfer system;    authenticating via the certificate authority the authority of the signer of the signed document to assent to payment of the invoice;    storing a copy of the signed digital document in a database associated with the transfer network system;    sending a payment authorization request from the network transfer system to the first party;    signing the payment authorization request using a second digital certificate in accordance with the procedure of the certificate authority;    sending the signed payment authorization request from the first party to the network transfer system electronically;    authenticating via the certificate authority the authority of the signer of the signed payment authorization request to assent to the transfer of funds from the financial account of the first party at the first agent to the financial account of the second party at the second agent;    storing a copy of the signed payment authorization request in the database associated with the transfer network system;    sending a copy of the signed payment authorization request to the first agent;    creating an electronic payment instruction verifying the transfer of finds out of the financial account of the first party at the first agent;    sending this electronic payment instruction from the first agent to the transfer network system;    forwarding the electronic payment instruction to the second agent;    creating an electronic payment receipt verifying the transfer of funds into the financial account of the second party at the second agent; and    sending the electronic payment receipt from the second agent to the transfer network system.    
     
     
         2 . A secure messaging system for supporting financial transactions with finality between a first client having an account at a first financial institution and a second client having an account at a second financial institution, the secure messaging system comprising: 
 a transfer network system comprising a messaging server configured to send and receive messages from a communications medium and further comprising an audit database;    a first client system connected to the transfer network system via the communications medium, the first client system being associated with the first client;    a second client system connected to the transfer network system via the communications medium, the second client system being associated with the second client;    a validation server in communication with the transfer network system, the validation server configured to provide authentication of the identity of at least one individual user of the first client having authority to assent to the payment of funds from an account of the first client to an account of the second client,    a first financial institution client system connected to the transfer network system via the communications medium and associated with a first financial institution, the first financial institution having an account holding funds of the first client;    a second financial institution client system connected to the transfer network system via the communications medium and associated with a second financial institution, the second financial institution having an account holding funds of the second client.    
     
     
         3 . A handshaking system for secure message routing, comprising: 
 sending a digitally signed message and first authentication certificate from a first party to a network transfer system;    verifying a digital signature of said digitally signed message and validating said first authentication certificate;    sending a primary authorization request from said network transfer system to said first party;    sending a signed primary authorization response and second authentication certificate from said first party to said network transfer system;    verifying a digital signature of said signed primary authorization response and validating said second authentication certificate;    sending a first confirmation request to a second party;    sending a signed confirmation response and third authentication certificate from said second party to said network transfer system;    verifying a digital signature of said signed confirmation response and validating said third authentication certificate;    sending a secondary authorization request to said second party;    sending a signed secondary authorization response and fourth authentication certificate from said second party to said network transfer system; and    verifying a digital signature of said signed secondary authorization response and validating said fourth authentication certificate.    
     
     
         4 . The method of  claim 1 , further comprising sending a first acknowledgement to said first party when said first confirmation request is sent to said second party.  
     
     
         5 . The method of  claim 1 , further comprising sending a second conformation request to said first party upon verifying said digital signature of said signed secondary authorization response.  
     
     
         6 . The method of  claim 1 , further comprising sending a second conformation request to said second party upon verifying said digital signature of said signed secondary authorization response.  
     
     
         7 . The method of  claim 1 , further comprising sending a second conformation request to said first party and a third confirmation request to said first party upon verifying said digital signature of said signed secondary authorization response.  
     
     
         8 . The method of  claim 1 , further comprising logging each message received from said first party and from said second party in an audit file.  
     
     
         9 . The method of  claim 1 , further comprising logon of one or more workstations used by said first party to send messages to said Network Transfer System, where said logon includes validation of said logon using an out-of-band channel.  
     
     
         10 . The method of  claim 1 , further comprising logon of one or more workstations used by said second party to send messages to said Network Transfer System, where said logon includes validation of said logon using an out-of-band channel.  
     
     
         11 . The method of  claim 1 , wherein said first party comprises a first user and a second user, wherein said first authentication certificate is personal to said first user and said second authentication certificate is personal to said second user.  
     
     
         12 . The method of  claim 1 , wherein said second party comprises a first user and a second user, wherein said third authentication certificate is personal to said first user and said fourth authentication certificate is personal to said second user.  
     
     
         13 . The method of  claim 1 , wherein said first party receives said first authentication certificate when said first party performs a login to a computer that has performed a logon to the Network Transfer System.  
     
     
         14 . The method of  claim 13 , wherein said first authentication certificate is received in when said first party performs a login to the Network Transfer System.  
     
     
         15 . The method of  claim 1 , further comprising: 
 logging each message received from said first party and from said second party in a system audit file maintained by said Network Transfer System;    logging each message received from said Network Transfer System in a workstation audit file maintained by a workstation of said first party; and    detecting security breaches by comparing records in said system audit file with records in said workstation audit file.    
     
     
         16 . The method of  claim 1 , further comprising logon of a workstations used by said first party to send messages to said Network Transfer System, where said logon includes validation of said logon using an out-of-band channel.  
     
     
         17 . The method of  claim 16 , wherein said logon creates a secure VPN-like connection between said workstation and said Network Transfer System.  
     
     
         18 . The method of  claim 16 , wherein said secure VPN-like connection provides one or more secure messaging services.  
     
     
         19 . The method of  claim 18 , wherein said one or more secure messaging services includes instant messaging.  
     
     
         20 . The method of  claim 18 , wherein said one or more secure messaging services includes document transfer.  
     
     
         21 . The method of  claim 18 , wherein said one or more secure messaging services includes transfer of forms.  
     
     
         22 . The method of  claim 21 , wherein said one or more secure messaging services includes transfer of forms, and wherein said Network Transfer System verifies data in fields of said forms.  
     
     
         23 . A method for secure message transmission, comprising: 
 performing a workstation logon to a network transfer system using an out-of-band channel to validate said workstation;    performing a user login a said workstation, said user receiving a credential at login, said credential provided by said network transfer system;    create a message to be sent;    create a message audit file;    send said message audit file to said network transfer system;    attach said credential to an attribute field of a digital signature and digitally sign and encrypt said message to create an encrypted message;    send said encrypted message to said network transfer system as a received message;    compare said message audit file and said received message to validate said received message;    create a validation response; and    send said validation response to said workstation.    
     
     
         24 . A method for restructuring authenticity and authorizations used for control of electronic processes and electronic message handling, comprising; 
 identifying a digital certificate corresponding to a digital signature, said digital certificate comprising at least one signature attribute;    locating an attribute identity component of said signature attribute;    comparing said attribute identity component with a certificate distinguished name;    comparing said attribute identity component with a family of certificate attributes;    extracting named critical attribute values corresponding to said distinguished name and critical identity names and attributes    recombining said named critical attribute ordered according to associated identities of said named critical attributes to produce recombined attributes;    signing said recombined attributes to produce a recombination signature; and    sending and reserving said recombination of attributes for additional authorizations    
     
     
         25 . The method of  claim 24 , further comprising attributing an attribute to an individual user.  
     
     
         26 . A method for electronic message handling, comprising: 
 identifying a digital certificate corresponding to a digital signature having correspondence, said digital certificate comprising at least one signature attribute;    identifying a digital certificate Family Distinguished Name corresponding to a digital signature having correspondence with said digital certificate and said digital signature, said digital certificate comprising at least one signature attribute;    corresponding attribute components belonging to the signature attribute with hierarchical attribute components belong to said digital certificate Family Distinguished Name as represented in a hierarchical taxonomy;    constraining electronic Business Processes and electronic controls associated with said Family Business Process and Family electronic controls to the electronic Business Processes and electronic controls of the individual    associating and constraining Business Process policies of the Family to controls on the individual.    
     
     
         27 . The method of  claim 26 , further comprising attributing an audit trail of Business Processes to said individual.  
     
     
         28 . The method of  claim 26 , further comprising locating an attribute identity component of said signature attribute.  
     
     
         29 . A method for abuse management in a secure messaging system, comprising: 
 real-time auditing of messages sent between a network transfer system and a user, comprising:    assigning a quality-of-logon attribute to a digital signature used by a user workstation based on a security level of said user workstation;    validating portions of a digital signature associated with said messages;    authenticating a user certificate attached to said messages; and    checking fields of said message to detect modification of fixed fields;    and audit trail auditing of said messages by at least comparing message audit files maintained by a user workstation with audit files maintained by said network transfer system to identify discrepancies in said audit file.    
     
     
         30 . The method of  claim 29 , further comprising: using an out-of-band channel to validate a said user workstation each time said workstation performs a logon to the network transfer system.  
     
     
         31 . The method of  claim 29 , further comprising: assigning said user certificate to said user each time said user performs a login to the network transfer system.  
     
     
         32 . A method for establishing and maintaining an secure message transfer system, comprising: 
 using digitally-signed software to run on the system;    disallowing systems to perform transactions beyond their level of trust;    disallowing users to perform actions that exceed their authority;    securing messages by encryption;    comparing messages with audit records;    comparing sent messages with received messages;    repairing breaches in integrity;    halting forward progress when integrity has been breached;    alerting users and administrators to integrity breaches; and    generating profiles from previous breaches for detection and protection from future breaches.    
     
     
         33 . The method of  claim 32 , further comprising establishing level of trust for components of the system.  
     
     
         34 . The method of  claim 32 , further comprising establishing the level of trust in a client system based on the level of trust of the hardware, security implementation, and policies and procedures of the client.  
     
     
         35 . A Network Transfer System, comprising: 
 a Gateway configured to store and forward messages between one or more remote clients or servers and the Network Transfer System;    a Validation Server configured to authenticate users that are sending information using the Network Transfer System;    a Workflow Engine configured to script activity and provide exchange of internal messages between components of the Network Transfer System; and    an End-to-End Transaction Manager configured to manage secure message routing between users of the Network Transaction System.    
     
     
         36 . The Network Transfer System of  claim 35 , further comprising an Abuse Server configured to detect abuse of the Network Transfer.  
     
     
         37 . The Network Transfer System of  claim 35 , further comprising a Message Server configured to provide instant messaging authorized participants through the Network Transfer System according to a level of authority for each participant.  
     
     
         38 . The Network Transfer System of  claim 35 , further comprising an Audit Server configured to audit data transactions in the Network Transfer System.

Join the waitlist — get patent alerts

Track US2005257045A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.